Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Remove the Passphrase from an Apache SSL Key

This guide shows you how to remove the password from an SSL private key, so Apache can start without asking for it. It needs root access, so it fits a VPS or dedicated server.

Domains and DNS2 min read8 steps

What is an SSL key?

SSL makes a website safe, so the address starts with https://. It uses two files. The certificate is the public ID card. The private key is a secret file that proves the certificate is yours. Keep the private key secret.

What is a passphrase?

A passphrase is a password that locks the private key file. If the key has one, Apache asks you to type it every time it starts. That is a problem if the server restarts by itself at night. Apache will wait for a person to type, and your site stays offline.

Warning: A key without a passphrase is less protected. Anyone who copies the file can use it. Lock the file permissions after this step. Also keep an untouched backup of the original key.

Steps

  1. Log in to your server with SSH as root.
  2. Go to the folder where your key is. The path varies. Common ones are /etc/ssl/private or /etc/pki/tls/private.
  3. Back up the original key.
cp server.key server.key.orig

This makes a safe copy of the locked key.

  1. Run the OpenSSL command that writes a new key without a passphrase.
openssl rsa -in server.key.orig -out server.key

This reads the locked key, asks for the passphrase, and saves an unlocked copy as server.key.

  1. Type your current passphrase when asked. You see a message such as writing RSA key.
  2. Make the file readable only by root.
chmod 600 server.key
chown root:root server.key

These commands stop other users from reading the key.

  1. Test your Apache setup.
apachectl configtest

This checks your Apache settings for mistakes. It should say Syntax OK. On some systems the command is apache2ctl or httpd -t.

  1. Restart Apache.
systemctl restart httpd

This restarts the web server. On Debian and Ubuntu, use apache2 instead of httpd.

Check it

Apache should restart without asking for a password. Open your site with https:// to confirm.

How to check if a key has a passphrase

Open the key file as text. If the top line says ENCRYPTED, it has a passphrase.

Quick recap

  • A passphrase locks your private key.
  • Apache stops at startup to ask for it.
  • Use openssl rsa -in ... -out ... to remove it.
  • Back up first and set file permission to 600.
  • Test and restart Apache.